200-201 Security Policies and Procedures Practice Question
A security manager is drafting a data classification policy and wants to ensure handling requirements are applied consistently. Which TWO elements should the policy define for each classification level? (Choose two.)
⚠ Common exam trap
The trap here is treating an operational detail like an approved product list as a core policy element, when classification policy must define handling rules and accountability instead.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Labeling conventions and handling rules for storage, transmission, and disposal
An effective classification policy defines both how data at each level is labeled and handled, and who is accountable for it. Labeling and handling rules make the classification operational, while owner, custodian, and user responsibilities make it enforceable. Product selections, recovery objectives, and user rosters belong in supporting documents rather than the classification policy itself.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The maximum acceptable recovery time for each business application
Why it's wrong here
Recovery time objectives belong in business continuity and disaster recovery planning, where they are derived from impact analysis. They describe how quickly a service must be restored, not how data of a given sensitivity must be handled. Including them in a classification policy conflates availability planning with confidentiality controls and would confuse readers about the policy's purpose.
- ✗
A list of every employee authorized to access each data repository
Why it's wrong here
Enumerating individual users in a policy is impractical because access changes constantly and the list would be outdated immediately. Access decisions should flow from roles and least-privilege principles documented elsewhere, with the classification level determining the required controls. Embedding user lists in policy also creates a maintenance burden and potential privacy exposure without improving classification consistency.
- ✗
The specific vendor products approved for encrypting each data type
Why it's wrong here
Naming approved products can be useful in a standards document, but it is too volatile to belong in the core classification policy. Products change, and tying classification levels to specific vendors makes the policy stale and hard to maintain. The policy should require controls such as encryption for a given level, leaving product selection to supporting standards and architecture guidance.
- ✓
Labeling conventions and handling rules for storage, transmission, and disposal
Why this is correct
A workable classification policy must state how each level is marked and how it must be stored, transmitted, and destroyed. Without labeling conventions, users cannot tell which rules apply, and without handling rules the classification has no operational effect. These elements translate an abstract label into concrete daily behavior, which is what makes the policy enforceable and auditable across departments.
- ✓
Roles and responsibilities for data owners, custodians, and users
Why this is correct
Classification only works when someone is accountable for assigning labels and someone is responsible for protecting the data. Defining data owners, custodians, and user obligations removes ambiguity about who approves access, who applies controls, and who reports mishandling. This accountability structure is what allows the policy to be enforced and reviewed over time rather than remaining aspirational.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.